Privacy Policy
This policy explains how Semlens handles information when you visit the public site, create an account, use the workspace, or connect an optional service.
Who this policy applies to
This policy applies to people who visit Semlens public pages, contact Semlens, or use an authenticated Semlens account and workspace.
Information you provide
- Account and profile information, including your email address, display name, profile image, authentication provider, and information needed to manage your account and sessions.
- Workspace content, including designs, uploads, brand assets, reusable templates, graphics, text, media, and instructions you submit for processing.
- Board configuration, followed RSS or Reddit sources, and research you choose to save with stories.
- Contact submissions, including your name, email address, subject, message, and limited security metadata used to prevent spam and duplicate submissions.
- In-workspace feedback, including the report or message you submit, optional screenshots or text evidence you explicitly attach, account identity used for internal support follow-up, and limited page context used to understand the submission.
Information generated through use
Semlens creates records needed to operate the service. These can include authentication and session state, billing and subscription status, template previews, exports, processing jobs, publishing attempts, connected-account status, and security, diagnostic, or audit records.
When you send in-workspace feedback, Semlens may record your account identity, a sanitized workspace path, and coarse route category so the team can understand who sent it and where it originated without storing query strings or raw private URLs for that feedback.
When you authorize MCP access, Semlens records the authorization and application activity needed to apply access rules and maintain an audit trail for supported actions.
How Semlens uses information
Semlens uses information to:
- Provide and secure accounts, sessions, and private workspaces.
- Save, display, process, preview, and export your work.
- Operate billing, subscriptions, one-time credit-pack purchases, generation-credit balances, and account management.
- Follow the sources you configure and retain research you ask Semlens to save.
- Carry out optional AI, image-editing, publishing, and connected-service actions that you request.
- Prevent abuse, investigate failures, maintain auditability, and improve service reliability.
- Respond to Contact submissions, in-workspace feedback, and privacy requests.
AI and media processing
AI and media features are optional and run when you choose to use them. Depending on the action, Semlens may send the prompt, source context, image, or other selected content needed to complete the request to Google or OpenAI. Other actions may use app-operated media and background-removal workers.
When you choose Research or Find media, Semlens sends the selected story and available source context to OpenAI to search the web and prepare results. Find media may also retrieve and process third-party image previews and video posters supplied by source sites so Semlens can validate and privately cache usable previews.
Studio generation can use prompts, source context, templates, Brand Kit selections, and private reference images that you explicitly attach. Semlens stores reusable references and generated results privately. Google or OpenAI processes the content needed for the image model you select and may retain request data according to its own terms and privacy practices.
Create From Story uses the story context and instructions you provide to prepare a design draft. Image editing and background removal process the media you select and may create output files and processing records for the workspace. Image-generation results depend on the selected model; Semlens does not guarantee exact logo, template, or reference reproduction.
Service providers and connected services
Semlens shares information with providers only as needed to operate the service or complete an action you direct:
- Supabase provides authentication, database, and file-storage services.
- Stripe handles checkout, subscriptions, one-time credit-pack payments, invoices, payment methods, and billing management. Semlens retains billing records needed to show and reconcile subscription, purchase, refund, dispute, and credit state.
- Railway hosts application services and app-operated processing workers.
- Trello may be used as an internal issue-tracking mirror for a bounded feedback summary, reporter context, and evidence-file count so the team can triage and follow up. Private feedback attachments remain in private storage and are not attached to the Trello card.
- Google provides optional Google sign-in when you choose that authentication method.
- Google Analytics, PostHog, and Microsoft Clarity may provide optional analytics for public site visits, public-page UX patterns, and coarse product milestones when analytics is enabled. Semlens does not send design documents, captions, asset URLs, billing identifiers, feedback text, or raw user content in analytics events.
- Google supports image-generation processing you request. OpenAI supports image generation and the Research and Media web-search processing you request.
- Meta and Instagram handle optional account connection and publishing actions. Semlens keeps connection, credential, publishing, and result records needed to operate that feature.
These providers process information under their own terms and privacy practices in addition to the controls Semlens applies.
Cookies and browser storage
Semlens uses essential cookies for authentication, session continuity, email changes, and optional connected-service authorization flows.
Browser storage supports limited product functions such as editor clipboard data, template-to-editor handoff, and migration of older source-monitoring configuration. Some development, diagnostic, or analytics options may also use browser storage when enabled. Semlens does not describe these essential product uses as an advertising-cookie program.
Public and private content
Private workspace records are intended for authenticated, owner-scoped access. Public template pages expose only content approved for public discovery, including published metadata and previews. Content you deliberately publish, share, or export can leave the private workspace and may be retained by its recipient or destination service.
Retention
Semlens keeps account and workspace information while it is needed to provide the service, maintain the account, complete user-directed processing, preserve audit integrity, or satisfy legitimate billing, security, and operational needs. Categories without an approved fixed period are removed according to those purposes and the controls available in the product.
Contact submissions, in-workspace feedback, and optional private feedback evidence are retained for up to 180 days and expired records and objects are removed through controlled maintenance. Limited anti-abuse records are kept for a shorter operational period.
Connected services and other providers may retain their own records under their terms, legal obligations, and retention practices.
Account deletion and user choices
Account settings let you correct profile details, request an email change, manage supported connections, and disconnect an Instagram account. You can export finished graphics through the editor, but a graphic export is not a complete export of all personal information associated with your account.
You can request account deletion through Security settings. Account deletion removes the account and owned workspace data covered by that flow, but it may not immediately remove provider records, billing records retained for legal or accounting reasons, backups, public or shared content, audit records, or other information retained for legitimate purposes.
For access, correction, deletion, or other privacy questions, email support@semlens.com. Semlens may need to verify the request before acting on it.
Security
Semlens uses authenticated access, owner-scoped workspace records, server-controlled privileged actions, protected connected-account credentials, and reasonable technical and organizational safeguards. No system can guarantee complete security.
International processing and privacy rights
Semlens and its providers may process information in more than one country. Privacy rights vary by location and may include rights to access, correct, or request deletion of personal information. Contact Semlens to make a request, and the request will be handled according to applicable requirements.
Policy changes
This policy may change as Semlens and its legal obligations evolve. The effective date at the top of this page identifies the current published version.
Contact
Send privacy questions or requests to support@semlens.com. You may also use the public Contact form.